As a Cybersecurity / Trellix-HBSS Engineer, you will support the implementation, administration, testing, and maintenance of Trellix/HBSS endpoint security capabilities while contributing to broader cybersecurity and Information Assurance activities. You will work with systems, infrastructure, integration, test, and cybersecurity teams to support the implementation and verification of security requirements within Department of Defense computing environments.
Approximately 50–75% of this position will focus on Trellix/HBSS engineering activities, including installation and configuration of Trellix COTS products, endpoint management, policy development, security testing, troubleshooting, upgrades, and maintenance. The remaining effort will support cybersecurity compliance activities including vulnerability and configuration scanning, analysis and reporting of findings, remediation tracking, collection of objective evidence, and preparation and routing of cybersecurity documentation.
This position provides an opportunity to develop specialized expertise in enterprise endpoint security, Information Assurance, and Department of Defense cybersecurity compliance.
What you’ll experience:
- Installing, configuring, testing, and administering Trellix/HBSS technologies across Windows and Linux environments
- Supporting the development and implementation of endpoint security policies based on system and cybersecurity requirements
- Executing security testing and evaluating the implementation of security requirements
- Supporting vulnerability scanning, system hardening, remediation, and DoD cybersecurity compliance activities
- Developing and maintaining security documentation and supporting technical evidence
- Collaborating with cybersecurity, systems, infrastructure, integration, and test engineering teams
What you bring to the table:
- Bachelor’s degree in Engineering, Cybersecurity, Computer Science, Information Technology, or a related Science or Mathematics field plus 1 year of relevant experience; or a Master's degree
- Clear understanding of systems engineering and cybersecurity concepts, principles, and practices
- Working knowledge of Windows and/or Linux operating systems and fundamental system administration concepts
- Familiarity with COTS software installation, configuration, and support
- Familiarity with cybersecurity specifications and guidance including Risk Management Framework (RMF), DISA STIGs, and other government security requirements
- Understanding of security testing, verification, and validation processes
- Ability to troubleshoot software, services, configurations, and system connectivity
- Ability to analyze technical and cybersecurity findings and clearly identify and report system security concerns
- Clear written and verbal communication skills and ability to work effectively within multidisciplinary engineering teams
Responsibilities may include:
- Install, configure, maintain, test, and troubleshoot Trellix/HBSS products and associated endpoint components
- Support administration of Trellix ePolicy OGregGregrchestrator (ePO), Trellix Agent, Endpoint Security (ENS), and associated technologies
- Support the development, configuration, testing, deployment, and maintenance of Trellix security policies
- Validate configuration and policy changes in representative lab or test environments with applicable security policies and controls enforced
- Monitor endpoint health, agent communications, security events, content currency, and policy application across supported systems
- Troubleshoot agent communication, policy enforcement, and application compatibility issues; identify contributing security controls and validate corrective actions through testing
- Evaluate interactions between application, platform, and site security policies, including policy inheritance and required exceptions
- Execute security testing and evaluate the implementation of applicable security requirements
- Execute and review vulnerability and security configuration scans; analyze, document, and track findings through remediation or disposition
- Support DISA STIG implementation, assessment, and documentation
- Develop and maintain installation procedures, Policy Layout Guides (PLGs), policy assignments, configuration-controlled packages, security documentation, and supporting technical evidence
- Collect and maintain cybersecurity Objective Quality Evidence (OQE) and support preparation and routing of cybersecurity compliance and Assessment and Authorization (A&A) documentation
- Coordinate with engineering and cybersecurity teams to investigate findings, recommend corrective actions, and verify remediation
What sets you apart:
- Experience with Trellix ePolicy Orchestrator (ePO), Trellix Agent, Endpoint Security (ENS), or HBSS
- Experience developing, modifying, or testing endpoint security policies
- Experience with ACAS/Nessus, Evaluate-STIG, DISA STIGs, SCAP Compliance Checker (SCC), Trivy, or similar cybersecurity assessment tools
- Familiarity with DoD Risk Management Framework (RMF) and Assessment and Authorization (A&A) processes
- Experience with Windows Server and/or Red Hat Enterprise Linux (RHEL)
- Familiarity with Active Directory, Group Policy, certificates, firewalls, or enterprise networking
- Experience with PowerShell, Bash, Python, Ansible, or other scripting and automation technologies
- Familiarity with Navy CANES or ESS environments, PLG development, configuration management, or deployed system validation
- Interest in developing deeper expertise in endpoint security and cybersecurity compliance